A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like credential IDs, bzm workspaces and bzm project Ids. Prior to this fix, anyone could see this list as a dropdown on the Jenkins UI.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Perforce
Perforce blazemeter |
|
| Vendors & Products |
Perforce
Perforce blazemeter |
Wed, 03 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A fix was made in BlazeMeter Jenkins Plugin version 4.27 to allow users only with certain permissions to see the list of available resources like credential IDs, bzm workspaces and bzm project Ids. Prior to this fix, anyone could see this list as a dropdown on the Jenkins UI. | |
| Title | Missing authorization in BlazeMeter Jenkins Plugin | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Perforce
Published: 2025-12-03T08:42:27.305Z
Updated: 2025-12-03T14:21:10.953Z
Reserved: 2025-11-20T11:26:48.612Z
Link: CVE-2025-13472
Updated: 2025-12-03T14:20:58.825Z
Status : Awaiting Analysis
Published: 2025-12-03T09:15:47.470
Modified: 2025-12-04T17:15:08.283
Link: CVE-2025-13472
No data.